| Name | Modified | Size | Downloads / Week |
|---|---|---|---|
| Parent folder | |||
| README.md | 2026-07-14 | 680 Bytes | |
| v1.2.1 -- Bug-bounty hardening (#42-#46) source code.tar.gz | 2026-07-14 | 1.1 MB | |
| v1.2.1 -- Bug-bounty hardening (#42-#46) source code.zip | 2026-07-14 | 1.3 MB | |
| Totals: 3 Items | 2.4 MB | 0 | |
Resolves the remaining internal bug-bounty findings:
- Magic-byte attachment verification (#43) — a file must match its extension's signature (blocks disguised uploads).
- CSRF on the last admin POST endpoints (#44).
- Reverse-proxy flood protection for the submission channel — per-IP nginx
limit_req, no IP logging (#46). - Randomised case numbers — no cross-tenant volume leak (#42).
- S3 missing object → 404 instead of 500 (#45).
See the [CHANGELOG](https://github.com/openwhistle/OpenWhistle/blob/main/CHANGELOG.md#121.